(a)
Designation of responsible Federal entity— The Secretary shall have primary responsibility within the Federal Government for sharing information about election cybersecurity incidents, threats, and vulnerabilities with Federal entities and with election agencies.
(b)
Presumption of Federal information sharing to the department— If a Federal entity receives information about an election cybersecurity incident, threat, or vulnerability, the Federal entity shall promptly share that information with the Department, unless the head of the entity (or a Senate-confirmed official designated by the head) makes a specific determination in writing that there is good cause to withhold the particular information.
(c)
Presumption of Federal and State information sharing from the department— If the Department receives information about an election cybersecurity incident, threat, or vulnerability, unless the Secretary makes a specific determination in writing that there is good cause to withhold the particular information, the Department shall promptly share that information with—
(1)
the appropriate Federal entities;
(2)
all State election agencies;
(3)
all election agencies that have requested ongoing updates on election cybersecurity incidents, threats, or vulnerabilities; and
(4)
all election agencies that may be affected by the risks associated with the particular election cybersecurity incident, threat, or vulnerability.
(d)
Technical resources for election agencies— In sharing information about election cybersecurity incidents, threats, and vulnerabilities with election agencies under this section, the Department shall, to the extent possible—
(1)
provide cyber threat indicators and defensive measures (as such terms are defined in section 102 of the Cybersecurity Information Sharing Act of 2015 (
6 U.S.C. 1501)), such as recommended technical instructions, that assist with protecting against and detecting associated risks;
(2)
identify resources available for protecting against, detecting, responding to, and recovering from associated risks, including technical capabilities of the Department; and
(3)
provide guidance about further sharing of the information.
(e)
Declassification review— If the Department receives classified information about an election cybersecurity incident, threat, or vulnerability—
(1)
the Secretary shall promptly submit a request for expedited declassification review to the head of a Federal entity with authority to conduct the review, consistent with Executive Order 13526 or any successor order; and
(2)
the head of the Federal entity described in paragraph (1) shall promptly conduct the review.
(f)
Role of non-Federal entities— The Department may share information about election cybersecurity incidents, threats, and vulnerabilities through a non-Federal entity, such as the Multi-State Information Sharing and Analysis Center.
(g)
Protection of personal and confidential information— If a Federal entity shares information about an election cybersecurity incident, threat, or vulnerability, the Federal entity shall—
(1)
minimize the acquisition, retention, use, and disclosure of personal information of voters, except as necessary to identify, protect against, detect, respond to, or recover from election cybersecurity incidents, threats, and vulnerabilities; and
(2)
take reasonable steps to protect confidential Federal and State information from unauthorized disclosure.
(h)
Duty To assess possible cybersecurity incidents—
(1)
Election agencies— If an election agency becomes aware of the possibility of an election cybersecurity incident, the election agency shall promptly assess whether an election cybersecurity incident occurred and notify the State election official.
(2)
Election service providers— If an election service provider becomes aware of the possibility of an election cybersecurity incident, the election service provider shall promptly assess whether an election cybersecurity incident occurred and notify the relevant election agencies consistent with subsection (j).
(i)
Information sharing about cybersecurity incidents by election agencies— If an election agency has reason to believe that an election cybersecurity incident has occurred with respect to an election system owned, operated, or maintained by or on behalf of the election agency, the election agency shall, in the most expedient time possible and without unreasonable delay (in no event longer than 3 calendar days after discovery of the incident), provide notification of the election cybersecurity incident to the Secretary.
(j)
Information sharing about cybersecurity incidents by election service providers— If an election service provider has reason to believe that an election cybersecurity incident may have occurred, or that an information security incident related to the role of the provider as an election service provider may have occurred, the election service provider shall—
(1)
notify the relevant election agencies in the most expedient time possible and without unreasonable delay (in no event longer than 3 calendar days after discovery of the possible incident); and
(2)
cooperate with the election agencies in providing the notifications required under subsections (h)(1) and (i).
(k)
Content of notification by election agencies— The notifications required under subsections (h)(1) and (i)—
(1)
shall include an initial assessment of—
(A)
the date and duration of the election cybersecurity incident;
(B)
the circumstances of the election cybersecurity incident, including the specific election systems believed to have been accessed and information acquired; and
(C)
planned and implemented technical measures to respond to and recover from the incident; and
(2)
shall be updated with additional material information, including technical data, as it becomes available.
(l)
Security clearance— Not later than 30 days after the date of enactment of this Act, the Secretary—
(1)
shall establish an expedited process for providing appropriate security clearance to State election officials and designated technical personnel employed by State election agencies;
(2)
shall establish an expedited process for providing appropriate security clearance to members of the Commission and designated technical personnel employed by the Commission; and
(3)
shall establish a process for providing appropriate security clearance to personnel at other election agencies.
(m)
Catalog of cybersecurity services— The Secretary—
(1)
shall make publicly available, including on the public website of the Department, a catalog of cybersecurity services that the appropriate Federal agencies can provide to election agencies and a point of contact for each service; and
(2)
may create a classified annex to the catalog and make it available only to election agency personnel with appropriate security clearance.
(n)
Protection from liability— Nothing in this Act may be construed to provide a cause of action against a State, unit of local government, or an election service provider.
(o)
Assessment of inter-State information sharing about election cybersecurity—
(1)
In general— The Secretary and the Chairman, in coordination with the heads of the appropriate Federal entities and appropriate officials of State and local governments, shall conduct an assessment of—
(A)
the structure and functioning of the Multi-State Information Sharing and Analysis Center for purposes of election cybersecurity; and
(B)
other mechanisms for inter-state information sharing about election cybersecurity.
(2)
Comment from election agencies— In carrying out the assessment required under paragraph (1), the Secretary and the Chairman shall solicit and consider comments from all State election agencies.
(3)
Distribution— The Secretary and the Chairman shall jointly issue the assessment required under paragraph (1) to—
(A)
all election agencies known to the Department and the Commission; and
(B)
the appropriate congressional committees.
(p)
Congressional notification—
(1)
In general— If an appropriate Federal entity has reason to believe that a significant election cybersecurity incident has occurred, the entity shall—
(A)
not later than 7 calendar days after the date on which there is a reasonable basis to conclude that the significant incident has occurred, provide notification of the incident to—
(i)
the appropriate congressional committees;
(ii)
the members of the Senate representing the States affected by the incident; and
(iii)
the members of the House of Representatives representing the congressional districts affected by the incident; and
(B)
update the initial notification under paragraph (1) within a reasonable period of time after additional information relating to the incident is discovered.
(2)
Reporting threshold— The Secretary shall—
(A)
promulgate a uniform definition of a “significant election cybersecurity incident”; and
(B)
shall submit the definition promulgated under subparagraph (A) to the appropriate congressional committees.